
Regulatory compliance

NIS2, DORA, ISO standards and GDPR in a single compliance path, with audit-ready evidence.
The challenge
Regulations overlap: the same measure serves NIS2, ISO/IEC 27001 and GDPR, yet it is often handled three times by three different people. We bring every regulation that applies to you into a single path — assessment, plan, implementation, evidence — so each effort counts for several obligations and the audit finds the proof ready.
NIS2 — Network and information systems security
The NIS2 directive, transposed in Italy by Legislative Decree 138/2024, extends security obligations to thousands of companies — essential and important entities — and also involves their suppliers and management bodies. We check whether and how it applies to you, measure the gap on the required measures and hand you a plan ordered by risk, not by chapter of the regulation.
- Applicability assessment and entity classification
- Gap analysis on the required security measures
- Incident handling and notification procedures
- Training for management bodies and staff
DORA — Digital operational resilience
For banks, insurers, financial intermediaries and their ICT suppliers, Regulation (EU) 2022/2554 requires proof that you can keep operating when something breaks. We map critical services and third-party dependencies, define the testing plan and align supplier contracts.
- Map of critical services and third-party dependencies
- Register of information on ICT suppliers
- Operational resilience testing plan
- Contract clauses to add with suppliers
ISO/IEC 27001 — Information security
We build the information security management system around the processes you actually have and guide you up to the certification audit: a system that lasts, not a binder written just to pass the exam.
- Scope, risk assessment and statement of applicability
- Policies and procedures built on real processes
- Internal audits, management review and support at the certification body's audit
ISO 9001 — Quality
Clear processes, defined responsibilities and measurable continuous improvement: we set up the quality management system and prepare you for the certification body's audit.
ISO 22301 — Business continuity
Impact analysis, continuity strategies and recovery plans tested in the field: to keep operating even when a system, a supplier or a site goes down.
ISO/IEC 20000-1 — IT service management
For those delivering IT services to internal or external customers: request, incident, change and service level management processes aligned with the standard, and measured.
ISO/IEC 42001 — Artificial intelligence
To use or develop artificial intelligence in a governed way: roles, risk assessment and controls according to the international standard for AI management systems.
GDPR — Personal data protection
From the processing register to ready answers when a data subject actually writes in: we rebuild the processing map around how you work today and leave procedures your team can carry out on its own.
- Processing register, privacy notices and legal bases
- Appointments and agreements with providers processing data on your behalf
- Procedures for data-subject requests and personal data breaches
What we deliver
- Map of the applicable regulations and of your compliance level
- Gap analysis with collected evidence and a remediation plan with priorities, timelines and owners
- Policies, procedures and registers built around your real processes
- Support during audits and authority inspections
- Training for staff and management bodies